Citing a report from the Council of Economic Advisers (CEA), the White House said on Friday that cyberattacks cost the US economy somewhere between $57 billion to $109 billion in 2016. The estimate includes losses from a wide variety of activities, such as DDoS attacks, data breaches, ransom demands, downed infrastructure, lost […]
Hacking
Null Character Bug Lets Malware Bypass Windows 10 Anti-Malware Scan Interface
Malware that embeds a null character in its code can bypass security scans performed by the Anti-Malware Scan Interface (AMSI) on Windows 10 boxes. Microsoft fixed this vulnerability last week when it released the February 2018 Patch Tuesday security updates. Flaw affects AMSI Windows 10 security feature The vulnerability resides […]
Free Ransomware Available on Dark Web
The McAfee Advanced Threat Research team recently analyzed a ransomware-as-a-service threat that is available for free and without registration. This malware was first seen in July 2017 with the extension .shifr. It has now appeared in recent detections with the extension .cypher. Ransomware-as-a-Service Ransomware-as-a-service is a cybercrime economic model that allows […]
Inside the Capabilities and Detection of UDPoS Malware
Imagine a job that changes every day of your life, where you get to do something new each week – that’s what it’s like working in the cybersecurity industry. For me, this is ideal—smarter adversaries, new challenges, and the constant struggle to predict and prepare for the future of security in […]
JenkinsMiner made $3.4 million in a few months by compromising Jenkins servers
Hacker Group Makes $3 Million by Installing Monero Miners on Jenkins Servers A criminal organization has made $3.4 million by compromising Jenkins servers and installing a Monero cryptocurrency miner dubbed JenkinsMiner. “The perpetrator, allegedly of Chinese origin, has been running the XMRig miner on many versions of Windows,and has already secured him over $3 million […]
The Mirai Botnet Is Attacking Again…
The Mirai Botnet Is Attacking Again… And the spinoff bots – and all their command and control hostnames buried in the morass of digital data – are hilarious. The Mirai botnet is kind of like Madonna. They both were huge once. Then the adoring public shifted their attention to younger, newer […]
Russian hackers sentenced to prison in US for compromising 160 million credit cards
Two Muscovites have been sentenced to years in prison for their roles in the biggest data breach conspiracy ever prosecuted in the United States. Three co-conspirators are still at large. Vladimir Drinkman, 37 and Dmitriy Smilianets, 34, had previously pleaded guilty for their roles in the conspiracy to commit wire […]
Hackers sentenced for SQL injections that cost $300 million
Heartland Payment Systems: remember that decade-old breach? What was then the sixth-largest payments processor in the US announced back in 2009 that its processing systems had been breached the year before. Within days, it had been classified as the biggest ever criminal breach of card data. One estimate claimed 100 million cards and […]
Russian, Indian banks lose millions to hackers
The Russian central bank’s Financial Sector Computer Emergency Response Team (FinCERT) disclosed on Friday that hackers compromised a computer at a Russian bank and used the SWIFT system to transfer 339.5 million roubles (around $6 million) to accounts they controlled. No details about the heist have been shared, so […]
DELL EMC PATCHES CRITICAL FLAWS IN VMAX ENTERPRISE STORAGE SYSTEMS
Dell EMC fixed two critical flaws in its management interfaces for its VMAX enterprise storage systems. One of the vulnerabilities could allow a remote attacker to use a hard-coded password to a default account to gain unauthorized access to systems. The company issued updates that address the two vulnerabilities, CVE-2018-1215 and CVE-2018-1216, on […]